using System;
using System.Data;
using System.Configuration;
using System.Collections;
using System.Web;
using System.Web.Security;
using System.Web.UI;
using System.Web.UI.WebControls;
using System.Web.UI.WebControls.WebParts;
using System.Web.UI.HtmlControls;
using System.Data.SqlClient;

public partial class ContactUs : System.Web.UI.Page
{
    protected void Page_Load(object sender, EventArgs e)
    {
        SqlConnection conn = new SqlConnection("data source=132.170.203.20;Initial Catalog=CET_4584;User ID=student;Password=password12");
        SqlDataReader rdr;
        SqlCommand cmd;

        String sqlPageId = "";
        pageNavigationLabel.Text = "";
        pageSubtitleLabel.Text = "";
        conn.Open();
        cmd = new SqlCommand("SELECT * FROM [pages] where CMSPage = 0 and Active = 1", conn);
        rdr = cmd.ExecuteReader();
        while (rdr.Read())
        {
            if (rdr["url"].ToString() == "ContactUs.aspx")
            {
                sqlPageId = rdr["id"].ToString();
                pageSubtitleLabel.Text = "<legend>" + rdr["subtitle"].ToString() + "</legend>";
            }
            pageNavigationLabel.Text += "<li><a href = '" + rdr["url"] + "'>" + rdr["title"] + "</a></li>";
        }
        conn.Close();

        conn.Open();
        cmd = new SqlCommand("SELECT * FROM [departments] Where Active = 1", conn);
        rdr = cmd.ExecuteReader();
        while (rdr.Read())
        {
            departmentId.Items.Add(new ListItem(rdr["dbname"].ToString(), rdr["id"].ToString()));
        }
        conn.Close();
    }
    protected void SubmitButton_Click(object sender, EventArgs e)
    {
        SqlConnection conn = new SqlConnection("data source=132.170.203.20;Initial Catalog=CET_4584;User ID=student;Password=password12");
        SqlCommand cmd;
        conn.Open();
        cmd = new SqlCommand("INSERT INTO [tickets] (email, department_id, dbname, telephone, comments) VALUES ('" + emailText.Text + "', " + departmentId.SelectedValue.ToString() + ", '" + nameText.Text + "', '" + telephoneText.Text + "', '" + commentsText.Text + "')", conn);
        cmd.ExecuteNonQuery();
        conn.Close();
        thankYouLabel.Text = "Thank you, you will hear from us shortly!";
    }
}
